cross platformrecovery

Ad Account Recovery Acceptance Checklist: Prove Operations Before Resuming Spend

Prove access, ownership, billing, dependencies, measurement, test delivery, monitoring, reconciliation, and closure before resuming ad spend.

Last verified July 19, 2026

Direct answer

Do not call an ad account recovered because login, case response, or campaign activity exists. Synthesis/inference: states are non-overlapping: access restored = authorized reachability; operations recovered = all gates pass for a named scope, with provider-dependent affected scope not accepted; outcomes settled = all material ledger differences for a stated cohort/cutoff resolved. Named residuals document work but never settle material differences. Administrative closure may record accepted/not-accepted scopes; it is not operational acceptance. Mutable mechanics require first-party verification. [DRS-A01][BC-S06][BC-S09][RS-S08]

Who this is for

Fit: finance, security, growth, agency, and incident leads after high-spend Meta, Google Ads, TikTok, or cross-platform access, payment, delivery, reporting, verification, automation, or regional incidents.

Not a fit: routine low-risk setup with healthy owner access; anyone seeking an “un-ban,” replacement account, identity/payment rotation, cloaking, forged records, anti-detect tools, appeal spam, indiscriminate chargebacks, or unverified credential handling. Operational—not legal, insurance, tax, banking, forensic, or platform-support advice. AdsInfra makes no recovery, timing, delivery, refund, ROAS, or reimbursement guarantee. [PR-P07][PR-P10][PR-P11]

Decision model

Three labels, not one green check

  1. Access restored: an authorized owner can reach the relevant surface. This does not establish ownership, clean sessions, partner removal, payment integrity, or connected-asset health. Manager access mechanics and compromised-account routes are not proof every linked asset is clean. [BC-S09][BC-S10][BC-S11]
  2. Operations recovered: authorized owner administers a named scope; persistence, billing, domains/catalogs/feeds, campaign/rules, measurement, and delivery gates pass. Provider-dependent affected scope remains not accepted. This is an operating synthesis, not a provider definition. [RS-S03][RS-S09][DRS-A01]
  3. Outcomes settled: all material billed, served-delivery, attribution, analytics, CRM/backend, bank/card, agency, refund, and dispute differences through defined cohort/cutoff are resolved; named residuals do not settle a material difference. [RS-S07][RS-S08]

Preconditions to open the gate

The incident lead must have incident ID/UTC chronology; platform, region, entity, account, asset, and case IDs; last-good export or unavailable note; authorized and finance owners; clean endpoint/security handoff if compromise is plausible; and a current first-party route. Missing any item means not ready. Preserve evidence and route the gap. [DRS-A01][RS-S03][PR-P03][PR-P10][PR-P13]

Hard stop and fail states

Stop and quarantine when access/persistence, authority, read-back, dependency blast radius, provider condition, event/test quality, ledger scope/cutoff, monitoring, or rollback is unresolved. Green status, completed script, or case response does not override these stops. [BC-S06][PR-P11][RS-S07]

Diagnostic or control sequence

Run the sequence in order. Each row names input, owner, action, and stop/branch condition. One approved reversible change at a time; do not mutate budgets, permissions, payments, domains, tracking, or rules concurrently. [RS-S03][RS-S09]

StepEvidence/inputOwnerActionStop/branch condition
1. Freeze the baselineIncident record; exact label/error; UTC time; account/object IDs; last-good export; recent-change log; status/case IDsIncident lead + recorderWrite observed symptom separately from hypotheses. Preserve exports, notices, headers, logs, and unavailable-data notes before cleanup.Stop if IDs, chronology, or authority cannot be verified. Screenshots remain supplemental context, not the only record. [DRS-A01][RS-S03]
2. Confirm custody and authorityLegal entity; full-control owner; manager/portfolio/business-center links; partner list; billing owner; contract/handoff recordAsset ownerVerify who can add/remove users, export assets, approve spend, and sign closure. Record every unknown as a named task.Stop if the person requesting changes is not the authorized decision owner. Do not transfer custody by sharing credentials. [BC-S09][VOC-F05]
3. Clean the access planeKnown-clean endpoint; user/admin/partner export; sessions; MFA/recovery contacts; OAuth apps; tokens; extensions; security noticesSecurity/asset ownerReset password/MFA/recovery contacts where applicable; revoke specifically identified suspect sessions/tokens/apps; compare before/after access.Stop if endpoint compromise is suspected, revocation fails, or an unknown administrator persists. Route to security/first-party recovery; do not relaunch. [BC-S10][BC-S11][PR-P12][BC-S18]
4. Validate payment and billing authorityPlatform balance/invoice/transaction IDs; bank/card record; agency invoice; authorized-user list; served-delivery periodFinance ownerBranch: suspected unauthorized activity; legitimate platform-balance disagreement; or agency/reseller invoice mismatch. Reconcile identifiers before choosing platform, issuer, bank, or counsel route.Stop a dispute if authorization, entity, currency, period, or transaction mapping is unresolved. Google warns that a chargeback against a legitimate Google Ads balance can lead to suspension; keep this account-specific and do not treat it as issuer advice. [PR-P11][BC-S08]
5. Map shared dependenciesParent/child containers; payment profile; domain/endpoint; catalog/feed; pixel/dataset; conversion configuration; vendors; rules/scripts/automationsOperations executor + asset ownerCompare the dependency graph with the incident scope. Record affected assets, owner, rollback, and independent health check for each shared object.Stop if disabling, rotating, or deleting one object could affect another entity/campaign and no owner-approved rollback exists. Synthesis/inference: nominally separate accounts are not independent when dependencies are shared. [RS-S17][RS-S18]
6. Reconcile campaign and rule statePreserved before-state; current campaigns/ad groups/ads; budgets/bids; targeting; creatives; feeds; rules/scripts; automation logsOperations executorProduce a change diff. For every intended mutation, perform platform read-back; treat a completed Google Ads Script run as insufficient because execution is best-effort.Stop if unexpected budget, destination, creative, targeting, rule, or feed changes remain unexplained. Roll back only through an authorized, bounded change. [BC-S06]
7. Validate measurement and destinationEvent schema/version; consent state; event samples/IDs; tag/API diagnostics; landing endpoint; analytics; CRM/backend recordMeasurement ownerTest destination/event through deduplication and the defined business record. Define cohort, timezone, attribution window, and settlement cutoff before comparing counts.Stop if events are stale, duplicated, misconfigured, consent-invalid, or untraceable. Do not call a metric gap a settled loss or platform cause. [RS-S07][RS-S08]
8. Run a bounded conversion testApproved test destination/campaign; unique test event/order/lead marker; expected record; owner-approved spend ceiling; alert recipientAsset owner + measurement ownerRun a low-risk authorized test in an approved mode where currently supported. Tag it; suppress unintended fulfillment/payment/customer communication and optimization/audience downstreams; exclude it from settlement cohorts and optimization inputs; verify no side effect; preserve evidence before cleanup.Stop on unauthorized spend, wrong destination, missing/duplicate event, unexpected audience/creative, side effect, or alert failure. Test mechanics require first-party verification. [RS-S07][RS-S08]
9. Reconcile incident-period ledgersPlatform-billed; served delivery; platform attribution; analytics/events; CRM/backend; bank/card; agency invoiceFinance owner + measurement ownerFreeze versioned extracts to the incident cohort and cutoff before restart. Record matches, latency, consent/attribution limits, disputed amounts, and residual owners; this checkpoint does not settle the later restart window.Status remains outcomes unsettled if any material difference is unresolved. Do not imply reimbursement or causality. [RS-S08]
10. Monitor a limited restartTest result; spend/delivery/event/access alerts; rollback threshold; communication planIncident leadApprove a staged, low-risk restart within authority and start the observation window. Watch spend, delivery, events, destinations, permissions, and incident signals; document read-back.Roll back or pause on any stop condition, alert gap, unauthorized change, or unexplained divergence. Platform delivery remains provider-dependent. [RS-S07][RS-S09]
11. Reconcile restart windowVersioned restart extracts; restart spend/delivery; events; attribution; analytics; CRM/backend; bank/card; agency records; post-restart cutoffFinance owner + measurement ownerAfter the observation window, freeze new extracts for the restart cohort/cutoff. Isolate seeded test artifacts and reconcile all material differences; update residuals.Outcomes remain unsettled if any material difference is unresolved. Administrative closure may record this scope as not accepted, but cannot upgrade it. [RS-S08]
12. Sign administrative closure and hand backEvidence index; both reconciliation checkpoints; acceptance results; residual register; monitoring owner; follow-up datesAsset owner + finance owner + incident leadSign accepted scope and separately record not accepted or outcomes unsettled scope, provider dependency, test cleanup, and next review; hand back decisions and revoke temporary access.No operational acceptance signature if residuals lack owner/action or monitoring is inactive. Administrative closure records status; it does not prove recovery or settled outcomes. [RS-S10][RS-S03]

Rollback logic

Before each change, record expected state, approver, rollback, signal, and blast radius. If read-back disagrees, stop; do not “fix forward.” Roll back only to an approved prior state that will not damage shared dependencies. If rollback is impossible/provider-controlled, quarantine spend/data, document the case, and escalate; never delete evidence. Synthesis/inference from [DRS-A01][RS-S09][BC-S06].

Evidence packet (minimum, no secrets)

  • Incident ID, collector, UTC timestamps, timezone, platform/surface, region, entity, account/container/object IDs, and exact labels/errors.
  • Last-good/current exports for access, campaigns, rules, billing, delivery, measurement, domains/catalogs/feeds, and parent/child links.
  • User/admin/partner/session/app/token changes; notices; headers; request IDs; case chronology; and attempted actions with expected/actual read-back.
  • Invoice/balance/transaction IDs, bank/card references, agency invoice, owner review, served-delivery, event samples, backend settlement, and cohort definition.
  • Evidence location, retention/access owner, redactions, unavailable records, and verification owner. Never send passwords, MFA codes, cookies, government IDs, full payment numbers, remote-control access, or scripts. [DRS-A01][BC-S18]

Post-recovery monitoring and review

For restart, assign owner, signals, frequency, alert recipient, and stop thresholds. Monitor spend/payment, delivery/budget, events/backend, destination/domain/catalog/feed, access/apps/tokens, automation read-backs, and symptom. Synthesis/inference: use actionable alerts. [RS-S07]

After the owner-selected observation window, hold a blameless review for material impact, unauthorized change, failed monitoring, or recovery beyond the objective; record chronology, evidence gaps, control changes, owners/dates, and a proving test. [RS-S09][RS-S10]

Evidence to preserve

Use the packet as closeout index. Preserve the before-state before changing shared objects; retain raw/read-only exports where permitted with collector, time, source, redaction, and access history. Apply privacy, retention, legal-hold, and provider terms; this is not a forensic mandate. [DRS-A01][RS-S03]

What not to do

Do not bypass restrictions with replacement/rented accounts, identity/payment rotation, cloaking, forged records, anti-detect tools, appeal spam, or speculative allegations. Do not trust unsolicited recovery messages or provide credentials, cookies, MFA codes, full payment data, government IDs, remote control, or scripts. Do not give blanket chargeback advice or relaunch on a green status, working login, completed script, or case reply. [PR-P07][PR-P10][BC-S06][PR-P11][BC-S18]

When to escalate

Self-service: healthy owner access, clear low-risk state, reversible change, specific first-party action. Platform: current review, security, billing, verification, or Account Health route. Finance/issuer/bank: authorization or settlement. Security/forensics: endpoint, session, token, or unauthorized activity. Counsel/broker/insurer: legal, contract, evidence-hold, or coverage questions. Country/region can affect TikTok business-verification document requirements, while TikTok transaction-appeal eligibility is case-by-case and can differ by account type; specialists cannot control provider outcomes. [PR-P03][PR-P10][PR-P11][PR-P13][PR-P14][PR-P15]

FAQ

Is a successful login recovery?

No. It is access restored only. Confirm authority, sessions/apps, partners, payment, dependencies, campaign/rule state, events, test conversion, monitoring, and sign-off before calling operations recovered. [BC-S09][BC-S10]

Can a platform case response close the incident?

No. It proves provider communication, not ownership, persistence, delivery, measurement, settled finance, or future eligibility. TikTok transaction-appeal eligibility is case-by-case and can differ by account type; do not infer regional appeal eligibility from PR-P15. [PR-P03][PR-P10][PR-P15]

Should we increase budget to test recovery?

No generic increase is justified. Use an owner-approved bounded test with a stop condition and independent event/backend read-back; it is not permission to resume normal spend. Synthesis/inference. [RS-S07][RS-S08]

When are outcomes settled?

Only when all material records reconcile to the same cohort and cutoff. Named owners, limitations, and next actions document unresolved differences but do not settle them. [RS-S08]

What if one dependency is still provider-dependent?

Mark operations not accepted for the affected scope and outcomes unsettled where material differences remain; quarantine restart and record the residual. Administrative closure cannot change those states. Do not conceal the dependency by relinking or creating a replacement account. [PR-P10][PR-P13]

Source appendix

All sources were accessed 2026-07-19.

KeySource title; author/publisher; publication dateURL
RS-S03Cybersecurity Incident & Vulnerability Response Playbooks; CISA; 2021https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
RS-S07Monitoring Distributed Systems; Rob Ewaschuk, Google SRE; 2017https://sre.google/sre-book/monitoring-distributed-systems/
RS-S08Service Level Objectives; Chris Jones, John Wilkes, Niall Murphy, Cody Smith, Google SRE; 2017https://sre.google/sre-book/service-level-objectives/
RS-S09Managing Incidents; Andrew Stribblehill, Google SRE; 2017https://sre.google/sre-book/managing-incidents/
RS-S10Postmortem Culture: Learning from Failure; John Lunney and Sue Lueder, Google SRE; 2017https://sre.google/sre-book/postmortem-culture/
RS-S17Mapping Disruption Sources in the Power Grid and Implications for Resilience; Maureen S. Golan and Javad Mohammadi; arXiv; 2022-07-17https://arxiv.org/abs/2207.08146
RS-S18Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks; John Matta, Jeffrey Borwey, Gunes Ercal; arXiv; 2014-04-01https://arxiv.org/abs/1404.0103
PR-P03Request a review if you are restricted from advertising on Meta platforms; Meta; undatedhttps://www.facebook.com/business/help/530209463124901/
PR-P07Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/
PR-P10Google Ads account suspensions overview; Google Ads Help; current/undatedhttps://support.google.com/adspolicy/answer/9841640?hl=en
PR-P11Billing and payment suspensions; Google Ads Help; current/undatedhttps://support.google.com/adspolicy/answer/13704200?hl=en
PR-P12Secure your Google Ads account: Introduction; Google Ads Help; current/undatedhttps://support.google.com/google-ads/answer/2375456
PR-P13About suspended ad accounts on TikTok; TikTok for Business; updated June 2026https://ads.tiktok.com/help/article/account-suspensions?redirected=1
PR-P14How to verify your business on TikTok; TikTok for Business; updated May 2026https://ads.tiktok.com/help/article/about-business-verification?aadvid=72391499277
PR-P15About transaction-related appeals; TikTok for Business; updated July 2026https://ads.tiktok.com/help/article/about-transaction-related-appeals
BC-S06Errors and Warnings; Google Ads Scripts team; updated 2026-06-24https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors
BC-S08How to dispute a Google Ads charge; Google Ads Help; current/undatedhttps://support.google.com/google-ads/answer/10560092
BC-S09Manager Accounts (MCC): About Google Ads manager accounts; Google Ads Help; current/undatedhttps://support.google.com/google-ads/answer/6139186
BC-S10If your account was hacked or someone is using it without your permission; Meta; current/undatedhttps://www.meta.com/help/policies/539039418231124/
BC-S11Recover a hacked or compromised business portfolio; Meta Business Help Center; current/undatedhttps://www.facebook.com/business/help/25302697499431030
BC-S18Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25https://www.group-ib.com/blog/meta-phishing-campaign/
DRS-A01Digital Evidence Preservation: Considerations for Evidence Handlers; Barbara Guttman, Douglas R. White, Tracy Walraven, NIST; 2022-09https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf
VOC-F05Sole Business Portfolio admin permanently disabled; u/Exact_Kiwi3437, Reddit; 2026-07-16https://old.reddit.com/r/FacebookAds/comments/1uxske3/sole_business_portfolio_admin_permanently/
shield_with_heartAdsInfra

Contact AdsInfra

Send a message about this resource before making a high-impact change.